Impact
Eventin, a WordPress plugin, failed to enforce ownership checks on event modification endpoints prior to version 4.1.21, allowing any user with contributor-level permissions or higher to add, edit, delete, or reassign events owned by other users, including administrators. The result is loss of data integrity and potential defacement of event content.
Affected Systems
The vulnerability affects any WordPress site running Eventin plugin versions earlier than 4.1.21. Site administrators should verify the installed plugin version and confirm that the site uses this plugin, regardless of vendor details as the CNA lists the vendor as Unknown:Eventin.
Risk and Exploitability
With a CVSS score of 8.1, the flaw is considered high severity and permits privilege escalation within the WordPress installation. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers would need contributor-level access to the website’s backend and can exploit the IDOR by targeting event URLs to modify or delete events belonging to other users.
OpenCVE Enrichment